Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects the use of package installation commands (pip, npm, npx) where the package name resembles popular AI/ML libraries (tensorflow, torch, openai, langchain) but is not an exact match for known legitimate versions. This is a common indicator of a typosquatting supply chain attack, where attackers attempt to trick users into installing malicious packages with similar names to trusted software.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
12 days ago
004
Detects Python or Pip processes that download an image file from the network and subsequently write a native extension module (.pyd or .so) to the disk within a 10-minute window. This behavior is consistent with the extraction of a hidden malicious payload embedded within an image file using steganography.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
203
Detects a single source IP address attempting to connect to multiple hosts over TCP port 3389 (RDP) within a short timeframe (10 attempts in 60 seconds). This behavior is indicative of a host scanning the network for accessible RDP services, a common precursor to lateral movement or brute force attacks.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
001
Detects high-frequency TCP connection attempts to WinRM (port 5985) originating from a single source host within the internal network. This pattern of behavior is often indicative of an adversary attempting to scan for or move laterally to multiple systems using WinRM.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
001
Detects multiple attempts to connect to administrative shares (ADMIN$, C$, IPC$) from a single source within a 60-second window. This pattern is indicative of automated lateral movement or enumeration attempts using the SMB protocol.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
001
Sweeps Defender Advanced Hunting telemetry for known Sauron Loader indicators: 5 malicious SHA256 hashes (MSI installer, rnp.dll loader, tdwp.dll decrypter, embedded RSA private/public key blobs) across file/process/image-load events, plus 4 C2 domains and their full URLs across network and DNS telemetry. No IP indicators were published in the source reporting (C2 is domain-based over HTTPS) — the IP bucket is intentionally omitted rather than filled with placeholder data.
avatar
Arnold Chan@slaz
Defender - KQL
13 days ago
205
Detects attempts to bypass the Antimalware Scan Interface (AMSI) in PowerShell by using reflection to modify internal AMSI-related structures and memory flags (e.g., AmsiUtils, amsiInitFailed). This technique involves manipulating system objects to neutralize AMSI's ability to inspect malicious script content.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects potential Golden Ticket forgery or malicious Kerberos activity by monitoring Windows Security Event IDs 4768 (TGT) and 4769 (TGS). The rule identifies suspicious characteristics including the use of weak encryption (RC4) where AES is preferred, specific ticket option flags commonly associated with Mimikatz, and unusually long ticket lifetimes that deviate from standard domain policies.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects the deletion of Volume Shadow Copies and disabling of Windows boot recovery options using native administrative utilities such as vssadmin, wmic, powershell, wbadmin, and bcdedit. This behavior is frequently associated with pre-encryption activities in ransomware attacks to prevent system restoration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects potential reflective DLL injection or process hollowing attempts by monitoring for high-privilege cross-process access (ProcessAccess EventID 10) or remote thread creation (CreateRemoteThread EventID 8). These methods are frequently used by attackers to execute malicious code within the memory space of a legitimate target process, thereby evading traditional signature-based detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects the suspicious execution of common Windows system binaries (LOLBAS) often used for proxying malicious code execution or deobfuscating payloads. This includes regsvr32.exe for remote scriptlet execution, mshta.exe for remote HTA execution, rundll32.exe for JavaScript or DLL function execution, and certutil.exe for decoding or retrieving remote files.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
201
Detects potential Pass-the-Hash (PtH) activity where a single user account performs NTLM Type 3 (network) authentications to three or more unique destination hosts within a 10-minute window, excluding service account activity (trailing $). This pattern is consistent with an adversary moving laterally across a network using harvested NTLM hashes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects attempts to bypass or tamper with the Antimalware Scan Interface (AMSI) in-memory by monitoring command lines of common script-hosting processes (e.g., PowerShell, WScript, Rundll32) for strings indicative of AmsiScanBuffer patching, reflection, or manual configuration of AMSI initialization states.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
101
Detects the use of the built-in Windows utility rundll32.exe to execute comsvcs.dll with the MiniDump command to dump the memory of the Local Security Authority Subsystem Service (LSASS) process. This is a common technique used by attackers to harvest credentials from memory.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects the use of native Windows utilities (vssadmin, wbadmin, bcdedit, wmic) to delete shadow copies, backup catalogs, or modify boot configuration data to disable recovery. This behavior is commonly associated with ransomware and data destruction attacks intended to prevent system restoration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
101
This rule detects unauthorized directory replication requests (DRSUAPI) using Active Directory Event ID 4662. It specifically monitors for access requests to sensitive directory replication object GUIDs (Get-Changes / Get-Changes-All) where the requesting user account is not a domain controller computer account. This behavior is a common indicator of DCSync credential dumping attacks performed by tools like Mimikatz or Impacket.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects the 'ClickFix' technique where a user copies a malicious payload and pastes it into the Windows Run dialog (Win+R). The rule monitors for the creation of registry values under the RunMRU key followed closely by the execution of powershell.exe or cmd.exe initiated directly by explorer.exe, indicating an bypass of standard browser execution chains.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
002
This rule detects persistence establishment via Scheduled Task creation shortly (within 15 minutes) after a suspicious PowerShell process execution. The PowerShell execution matches the 'ClickFix' pattern, characterized by hidden/bypass window styles and the invocation of remote download or execution cmdlets (e.g., IEX, IRM).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
102
This rule detects potentially malicious in-memory module loading, such as Beacon Object File (BOF) execution, on hosts already identified as exhibiting suspicious behavior related to MLTBackdoor or sideloading activity. It monitors for memory allocation or protection changes (AllocateVirtualMemory, VirtualProtect, CreateRemoteThread) that result in executable memory (RWX or execute-only) without a corresponding file on disk, which is a common indicator of fileless code injection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
002
This rule detects potential Browser-in-the-Browser (BitB) phishing attacks by identifying suspicious browser pop-up behavior (using window.open flags, hidden address/toolbars) on non-identity-provider domains, followed shortly by credential submission patterns on the same device. This pattern mimics legitimate OAuth or SSO windows to harvest user credentials.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
102
Detects anomalous access to the SharePoint WebPartPages.asmx SOAP endpoint, specifically using the GetWebPartPageConnectionInfo method. This query identifies patterns consistent with the exploitation of CVE-2026-65660, where adversaries attempt to smuggle WebPart template markup (e.g., <%@ Register, XamlServices) after legitimate preview methods have been disabled.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
003
Page 41 of 1870